CVE-2020-10607| Advantech WebAccess»º³åÇøÒç¶Âí½Å¹«¸æ

°ä²¼¹¦·ò 2020-04-22

0x00 ·ì϶¸ÅÊö



CVE   ID

CVE-2020-10607

ʱ   ¼ä

2020-04-22

Àà    ÐÍ

BO

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

Advantech WebAccess <=8.4.2




0x01 ·ì϶ÏêÇé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾




Advantech WebAccessÊÇÖйų́ÍåÑлª£¨Advantech£©¹«Ë¾µÄÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý½ÚÔ죬²¢ÌṩԶ³Ì½ÚÔìºÍÖÎÀí×Ô¶¯»¯É豸µÄÖ°ÄÜ¡£

Advantech WebAccess 8.4.2¼°Ö®Ç°°æ±¾ÖдæÔÚ»º³åÇøÒç¶Âí½Å£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ã»ÓÐÕýȷУÑéÓû§Ìá½»Êý¾ÝµÄ³¤¶È¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐдúÂë¡£CVSSÆÀ·Ö8.8¡£


0x02 ´ëÖý¨Òé


Ŀǰ³§ÉÌÒѰ䲼Éý¼¶²¹¶¡ÒÔ½¨¸´·ì϶£¬ÏêÇéÇë¹Ø×¢³§ÉÌÖ÷Ò³£º

https://www.advantech.com.cn/

´Ë±í£¬½¨ÒéÓйØÓû§Ó¦²ÉÈ¡µÄÆäËû°²È«·À»¤´ëÊ©ÈçÏ£º

£¨1£© ×î´óÏ޶ȵØÏ÷¼õËùÓнÚÔìϵͳÉ豸ºÍ/»òϵͳµÄÍøÂç¶³ö£¬²¢È·±£ÎÞ·¨´ÓInternet½Ó¼û£»

£¨2£© ¶¨Î»·À»ðǽ·À»¤µÄ½ÚÔìÏµÍ³ÍøÂçºÍÔ¶³ÌÉ豸£¬²¢½«ÆäÓëÒµÎñÍøÂç¸ôÀ룻

£¨3£© µ±±ØÒªÔ¶³Ì½Ó¼ûʱ£¬ÇëʹÓð²È«²½Ö裬ÀýÈçÐ鹹רÓÃÍøÂ磨VPN£©£¬²¢È·ÈÏVPN¿ÉÄÜ´æÔڵķì϶£¬Ð轫VPN¸üе½×îа汾¡£


0x03 ÓйØÐÂÎÅ


https://www.auscert.org.au/bulletins/ESB-2020.1084/


0x04 ²Î¿¼Á´½Ó


https://www.us-cert.gov/ics/advisories/icsa-20-086-01

https://nvd.nist.gov/vuln/detail/CVE-2020-10607

https://www.cnvd.org.cn/flaw/show/CNVD-2020-19926


0x05 ¹¦·òÏß


2020-03-26 CVE°ä²¼¸Ã·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾